CLAIMS 



We claim: 



5 LA method comprising: 

allowing a first subscriber to operate on an access network; 
allowing a second subscriber to operate on the access network; 

receiving a first indication that the first subscriber has been authenticated by a first 
service provider, and responsively assigning the first subscriber to operate in a first logical layer 
1 0 of the access network; 

receiving a second indication that the second subscriber has been authenticated by a 
□ second service provider, and responsively assigning the second subscriber to operate in a second 
;S logical layer of the access network; 

f handling communications in the first logical layer according to a first logic set; and 

:j|5 handling communications in the second logical layer according to a second logic set 

different than the first logic set. 

q 2. The method of claim 1, further comprising: 

jt; before receiving the first indication, assigning the first subscriber to operate in a default 

120 logical layer of the access network; and 

handling communications in the default logical layer according to a default logic set 
different than the first logic set. 

3. The method of claim 2, wherein the access network is an IP network, and 
25 wherein: 

the first logical layer comprises a first EP subnet; 

the second logical layer comprises a second IP subnet; and 

the default logical layer comprise a default IP subnet. 

30 4 - The method of claim 2, wherein handling communications according to the 

default logic set comprises disallowing a certain type of communication, and handling 
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communications according to the first logic set comprises allowing the certain type of 
communication. 

5. The method of claim 4, wherein the certain type of communication comprises a 
5 SIP communication. 

6. The method of claim 1, wherein handling communications in the first logical 
layer according to the first logic set comprises: 

disallowing communications from the first logical layer to outside of the access network. 

10 

7. The method of claim 1, wherein handling communications in the first logical 
q layer according to the first logic set comprises: 

jz{ disallowing a predetermined type of communication from passing from the first logical 

=C layer to outside of the access network. 

y 8. The method of claim 1, wherein handling communications in the first logical 

!«* layer according to the first logic set comprises: 

q detecting a web page being sent to an address on the first logical layer; and 

injecting into the web page information specific to the first service provider. 

jab 

9. The method of claim 8 5 wherein the information comprises an advertisement for 
the first service provider. 

10. The method of claim 1, wherein the access network is an IP network, and 
25 wherein: 

the first logical layer comprises a first IP subnet; and 
the second logical layer comprises a second IP subnet. 

11. The method of claim 1, wherein the subscriber communicates via an air interface 
30 with the access network. 
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12. A method comprising: 

allowing a first wireless subscriber to operate on an access network and assigning the first 
wireless subscriber to operate in a default IP subnet of the access network; 

allowing a wireless second subscriber to operate on the access network and assigning the 
5 second wireless subscriber to operate in the default IP subnet of the access network; 

receiving a first indication that the first wireless subscriber has been authenticated by a 
first service provider, and responsively assigning the first wireless subscriber to operate in a first 
IP subnet of the access network, the first IP subnet being different than the default IP subnet; 

receiving a second indication that the second wireless subscriber has been authenticated 
10 by a second service provider, and responsively assigning the second wireless subscriber to 
operate in a second IP subnet of the access network, the second IP subnet being different than the 
q default IP subnet and being different than the first IP subnet; 

JS handling communications in the default IP subnet according to a default logic set; 

■-f handling communications in the first IP subnet according to a first logic set different than 

>5> the default logic set; and 

handling communications in the second IP subnet according to a second logic set 
M different than both the default logic set and the first logic set. 

;if 1 3. A method comprising: 

p0 receiving from a subscriber on an access network an authentication request, the 

authentication request identifying the subscriber and identifying a designated service provider 
from among a plurality of service providers; 

sending the authentication request to the designated service provider; 

receiving from the designated service provider an authentication response indicating 
25 successful authentication of the subscriber by the designated service provider; 

responsive to the authentication response, assigning the subscriber to operate in a 
designated layer of the access network set aside for subscribers that have been authenticated by 
the designated service provider; and 

serving the subscriber in the designated layer of the access network. 

30 
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14. The method of claim 13, wherein the access network is an IP network and the 
designated layer is an IP subnet, and wherein assigning the subscriber to operate in the 
designated layer comprises assigning to the subscriber an IP address in the IP subnet. 



5 15. The method of claim 14, wherein serving the subscriber in the designated layer 

comprises handling communications with the subscriber according to a logic set established for 
the designated layer. 

16. The method of claim 15, wherein handling communications with the subscriber 
10 according to the logic set established for the designated layer comprises: 

detecting a packet bearing the IP address assigned to the subscriber; and 

O responsively applying the logic set to restrict transmission of the packet. 

S 

:«& 
: ■: 
•. r.Kr 

J 17. The method of claim 13, wherein serving the subscriber in the designated layer of 

• t j§5 the access network comprises: 

7" a gateway on the access network detecting a web page being sent to the subscriber; 

ji; the gateway modifying the web page to include an advertisement for the designated 

q service provider. 

}*> 18 - The method of claim 13, further comprising prompting the subscriber to provide 

the authentication request. 

19. The method of claim 18, wherein prompting the subscriber for the authentication 
request comprises: 

25 presenting to the subscriber a set of the plurality of service providers; and 

prompting the subscriber to select a service provider from among the plurality presented, 
wherein the subscriber selects the designated service provider from among the plurality. 

20. The method of claim 13, wherein the access network comprises a wireless access 
30 network. 
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21 . A method carried out by an access network, the method comprising: 

prompting a first client station to select a service provider from among a plurality of 

service providers, and receiving a signal from the first client station, indicating a first selected 

service provider; 

5 sending a first authentication request message for the first client station to the first 

selected service provider, the first authentication request message indicating authentication 
information for the first client station; 

receiving a first authentication response message from the first selected service provider, 
the first authentication response message indicating that first client station is authenticated by the 
10 first selected service provider; and 

in response to the first authentication response message, restricting the client station to 
O communications in a first logical layer of the access network associated with the first selected 
]d service provider. 

A 5 22. The method of claim 20, further comprising: 

prompting a second client station to select a service provider from among a plurality of 
I-* service providers, and receiving a signal from the second client station, indicating a second 
n selected service provider; 

jij sending a second authentication request message for the second client station to the first 

m selected service provider, the second authentication request message indicating authentication 

information for the first client station; 

receiving a second authentication response message from the second selected service 

provider, the second authentication response message indicating that second client station is 

authenticated by the second selected service provider; and 
25 i* 1 response to the second authentication response message, restricting the second client 

station to communications in a second logical layer of the access network associated with the 

second selected service provider. 

30 
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23. A communication system comprising: 

means for prompting a first client station to select a service provider from among a 
plurality of service providers, and for receiving a signal from the first client station, indicating a 
first selected service provider; 
5 means for sending a first authentication request message for the first client station to the 

first selected service provider, the first authentication request message indicating authentication 
information for the first client station; 

means for receiving a first authentication response message from the first selected service 
provider, the first authentication response message indicating that first client station is 
10 authenticated by the first selected service provider; and 

means for responding to the first authentication response message by restricting the client 
□ station to communications in a first logical layer of the access network associated with the first 
S selected service provider. 

Jjp 24. The communication system of claim 22, further comprising: 

means for prompting a second client station to select a service provider from among a 

i»* plurality of service providers, and for receiving a signal from the second client station, indicating 

iU 

P a second selected service provider; 

means for sending a second authentication request message for the second client station 
m to the first selected service provider, the second authentication request message indicating 

authentication information for the first client station; 

means for receiving a second authentication response message from the second selected 

service provider, the second authentication response message indicating that second client station 

is authenticated by the second selected service provider; and 
25 means for responding to the second authentication response message by restricting the 

second client station to communications in a second logical layer of the access network 

associated with the second selected service provider. 

30 
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